Malware

About “Barys.2263” infection

Malware Removal

The Barys.2263 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.2263 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Barys.2263?


File Info:

name: 9F1554BA3FAE7AC988DF.mlw
path: /opt/CAPEv2/storage/binaries/4a8341c7448c8804c4a896cd6c9f6cdc8533e26c36b424b808a5048b73fe9343
crc32: 10C09A08
md5: 9f1554ba3fae7ac988df6b218734704c
sha1: 4b404ff3bd1e165a04aea05a83272dd77c152285
sha256: 4a8341c7448c8804c4a896cd6c9f6cdc8533e26c36b424b808a5048b73fe9343
sha512: 11696729ab792d047d264edd96cf53f91a19ce4d15faa5cb2d825c8a91c00ad49f95f193f186d47d3e24b59cafaf78087a7d654409ce7a1ebde767f7a7c85a2d
ssdeep: 6144:f+M5CElofkFWQPtnRneqAKnvmb7/D269fgwMty0e6ndv0DEQ:fF5CLkFfnRnWKnvmb7/D26qndv0DV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17144A5136E29B03BF64388F0292C571738599D7A2695BC97B2827F1425B1AD3B9F430F
sha3_384: bde6f9d504a3fe6256d8fa6d8170f7c647697479ff362f42d167d9095a690c217bda6ab381ebf004a663a8753fb3ba63
ep_bytes: 68583e4000e8f0ffffff000000000000
timestamp: 2010-07-25 03:18:34

Version Info:

0: [No Data]

Barys.2263 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.low6
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.2263
FireEyeGeneric.mg.9f1554ba3fae7ac9
CAT-QuickHealWorm.VobfusVMF.S20098470
SkyhighBehavesLike.Win32.Generic.dm
McAfeeVBObfus.bu
MalwarebytesGeneric.Malware.AI.DDS
CynetMalicious (score: 100)
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2faa.None
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.36802.pqW@aeyZgzni
VirITTrojan.Win32.SHeur4.GCR
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AON
APEXMalicious
ClamAVWin.Worm.VB-1514
KasperskyWorm.Win32.Vobfus.efkf
BitDefenderGen:Variant.Barys.2263
NANO-AntivirusTrojan.Win32.VB.mjxgo
AvastWin32:Virtu-F [Inf]
RisingWorm.VobfusEx!1.99DB (CLASSIC)
EmsisoftGen:Variant.Barys.2263 (B)
BaiduWin32.Worm.VB.pw
F-SecureTrojan.TR/Otran.allue
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Barys.2263
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
SophosW32/Autorun-BTQ
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.AA.gen!Eldorado
AviraTR/Otran.allue
MAXmalware (ai score=82)
Antiy-AVLVirus/Win64.Expiro.rsrc
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Barys.D8D7
ZoneAlarmWorm.Win32.Vobfus.efkf
GDataGen:Variant.Barys.2263
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R15226
Acronissuspicious
VBA32BScope.Trojan.Diple
ALYacGen:Variant.Barys.2263
TACHYONTrojan/W32.Agent.253952.C
Cylanceunsafe
PandaW32/Vobfus.GEP.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!d6yKmr78f/w
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.F
AVGWin32:Virtu-F [Inf]
Cybereasonmalicious.a3fae7
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.6508cdfd

How to remove Barys.2263?

Barys.2263 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment